April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs

2026-04-16T07:23:36Z69004fbf5bd29aa92baaffa8f896cbd579a4479b260a1cf8b91824e4e38b2396
CVE-2026-20929ai-securityaxioscnappcritical-vulnerabilitiesdata-securitydns-cname-abusefalcon-serviceskerberos-relaynpmpatch-tuesdaysecure-bootsupply-chainwindowszero-day

What happened

CrowdStrike blog feed (Apr 2026) highlights the April 2026 Patch Tuesday releasing 164 CVEs, including two zero-days and eight critical vulnerabilities. Additional posts provide detection guidance for CVE-2026-20929 (Kerberos authentication relay via DNS CNAME abuse), report a likely STARDUST CHOLLIMA compromise of the axios npm package, and cover topics such as Windows Secure Boot certificate lifecycle management, AI security (Anthropic Mythos, Charlotte AI AgentWorks), accelerated exposure evaluation, CNAPP adversary-informed risk prioritization, data security, and expanded Falcon services.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
69004fbf5bd29aa92baaffa8f896cbd579a4479b260a1cf8b91824e4e38b2396
Enrichment time
2026-04-16T07:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.